Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Exposes Host Systems to Remote Code Execution Attacks A severe security flaw in a popular Node.js library has left developers scrambling to patch their applications and protect against potential remote code execution (RCE) attacks. The isolated-vm library, used by many organizations to execute untrusted JavaScript code within a sandboxed environment, contains a … Read more

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

A New Phishing Toolkit Emerges, Using Passkeys to Bypass Password Resets Cybersecurity researchers have uncovered a sophisticated new phishing toolkit that uses passkeys to maintain access to compromised accounts even after password resets. iAuthFlow V2, a malware toolkit available on Russian-language cybercrime forums for $10,000, has been analyzed by Abnormal researchers, who have revealed its … Read more

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

**New Attack Technique Exploits Flaw in AI Safety Guardrails, Raises Concerns Over Data Protection** A disturbing discovery by researchers at Adversa AI has shed light on a novel attack technique that bypasses safety guardrails in popular AI-powered chat platforms. Dubbed “Cryptographic Context Injection,” this tactic allows malicious actors to inject encrypted prompts into AI models, … Read more

Rust Supply Chain Attack Linked to North Korean Hackers

North Korean Hackers Strike at Rust Ecosystem with Sophisticated Supply Chain Attack In a brazen and well-planned attack, North Korean hackers have compromised one of the most popular open source software (OSS) projects in the world. The target was the Rust ecosystem, specifically the arrayref crate, an essential utility for converting arrays that has been … Read more

Critical Isolated-vm Vulnerability Leads to RCE on Host

A Critical Isolated-vm Vulnerability Has Been Discovered, Allowing Attackers to Take Control of Host Systems In a worrying development that highlights the ongoing cat-and-mouse game between security researchers and threat actors, a critical vulnerability has been discovered in isolated-vm, a popular Node.js library used by developers worldwide. The bug, which affects ExternalCopy, a function responsible … Read more

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Sophisticated Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets A new phishing toolkit has emerged, showcasing the rapidly advancing capabilities of cybercriminals. iAuthFlow V2, a malware tool sold on Russian-language cybercrime forums for $10,000, allows attackers to maintain access to victims’ accounts even after password resets. The toolkit’s primary mechanism is a “passkey” … Read more

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Cybersecurity researchers have uncovered a sophisticated attack technique that allows malicious actors to bypass safety guardrails in popular AI-powered chat interfaces, potentially exposing users’ sensitive data. The method, dubbed “Cryptographic Context Injection,” exploits the way these systems handle encrypted prompts. The discovery was made by Adversa AI, which reported its findings to xAI on June … Read more

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Cybersecurity Threats on the Rise: Recent Attacks Highlight Vulnerabilities in Systems and Infrastructure A spate of recent attacks has highlighted the ongoing threat landscape for cybersecurity professionals and individuals alike. From compromised networks to exploited vulnerabilities, these incidents serve as a stark reminder of the importance of robust security measures. One of the most concerning … Read more

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

A Perfect Storm of Cyber Threats: Zombie Cards, DDoS Attacks, and Exploited Vulnerabilities This week’s cybersecurity news is filled with a mix of alarming threats, ingenious attacks, and disturbing trends that highlight the evolving nature of cybercrime. From compromised network infrastructure to exploited vulnerabilities, we’ll break down the key stories and what they mean for … Read more

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

Retired US General Paul Nakasone Launches Boutique National Security Advisory Firm, Offering High-Level Cybersecurity Services to Private Clients Former US Army General Paul M. Nakasone, who led the National Security Agency and US Cyber Command until his retirement in February 2024, has launched a new national security advisory firm called The Nakasone Group. This boutique … Read more